Resolving WinCC Runtime Freeze on PCS7 V7.1 Systems

David Krause11 min read
SiemensTroubleshootingWinCC
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Resolving WinCC Runtime Freeze on PCS7 V7.1 Systems

WinCC Runtime (WinCC RT) in PCS 7 V7.1 environments can freeze immediately after activation, blocking screen buttons, suppressing error messages, and requiring termination from WinCC Explorer. This guide walks through the field-proven diagnostic sequence, including OS Project Editor verification, named-connection audit, SIMATIC Batch interaction, network-card driver status, and the SQL Server / MSMQ dependency that most often locks the runtime into a non-responsive state.

1. Problem Description

Symptom set reported on PCS 7 V7.1 with WinCC Runtime Professional / WinCC Explorer based runtime:

  • WinCC Runtime activates but the operator screen remains visually static.
  • No alarm messages, no error dialogs, no system-tray popup from WinCC Alarm Logging.
  • Softkeys at the bottom of every picture (login, language, hierarchy, alarm list, trend) are unresponsive to mouse and keyboard input.
  • Closing the runtime from the X button has no effect. Only the red Stop button in WinCC Explorer terminates the project.
  • The named connection (S7 connection via the PC station's IE General / IE ISO Industrial Ethernet card) was verified operational before the freeze; PLC tags can still be read via STEP 7 / NetPro diagnostic view.

When this symptom pattern is combined with a recent change (new SIMATIC Batch project, SQL Server patch, antivirus update, or change to a Broadcom / Intel network adapter driver), the freeze is almost always located in the WinCC server-side support services, not in the operator picture logic.

2. Architectural Background

WinCC Runtime is a multi-process service started by WinCC Explorer. The minimum required sub-processes are:

Service / Process Function Failure Mode
CCAlgLogServer Alarm Logging runtime Alarm list missing, MSMQ errors
CCTagLogServer Tag Logging runtime Trends/archives empty, freezes at start
CCLicense License handling RT demotes to demo mode
CCProjectMgr Project loader RT will not start, error 8001 / 8002
CCNS messenger Named connection transport (S7-MMC) Connection shows "Disconnected"
SQL Server (MSSQL$WINCC) Configuration + archive storage RT hangs during start, no PH displayed
Message Queuing (MSMQ) Alarm / Tag log queuing Hang on Tag/Alarm Logging start

Refer to the Siemens Support entry 109766432 for the documented MSMQ-related freeze on Alarm / Tag Logging activation, which matches the symptom profile in this article.

3. Root Cause Catalog

The five field-confirmed root causes for "Runtime appears to start but is non-interactive" are listed below in order of statistical frequency on PCS 7 V7.1 + Windows 7 / Server 2008 R2 stations.

3.1 OS Project Editor not run after creation / modification

The OS Project Editor in WinCC Explorer rebuilds the alarm / messaging database and the operator authorization scheme. If a project is restored from a backup or copied to another PC station and the OS Project Editor is not re-executed, the runtime can load the picture tree but cannot initialize the alarm subsystem, producing an apparent freeze. An empty plant-hierarchy (PH) bar at the top of the screen is the visual signature of this condition.

Path in WinCC Explorer: Project tree → OS → right-click → Open OS Project Editor. Click OK (or Apply) on every page to force regeneration, then restart the runtime.

3.2 Microsoft Message Queuing (MSMQ) service disabled

Alarm Logging and Tag Logging in WinCC rely on the Windows MSMQ service. If the service is set to Disabled or fails to start (often because the MSMQ sub-component is uninstalled), WinCC Runtime hangs during the activation of Alarm / Tag Logging. This is the canonical cause of the documented freeze on start-up.

  1. Open services.msc.
  2. Set Message Queuing (and the dependent Message Queuing Triggers) to Automatic.
  3. Start the service, then re-activate the WinCC runtime.

See the official knowledge base: 109766432 – Activating WinCC Runtime freezes during Alarm/Tag Logging.

3.3 SQL Server instance (MSSQL$WINCC) corrupted or stopped

All WinCC configuration data and runtime archives are stored in the named SQL Server instance MSSQL$WINCC. If this instance is stopped, blocked by a Windows update, or the master / model / tempdb files are damaged, the runtime will start the picture tree but block waiting for the database connection. Simatic Shell still works because it reads from local configuration files, masking the issue.

Diagnostic command in an elevated command prompt:

sc query MSSQL$WINCC
net start MSSQL$WINCC
sqlcmd -S .\WINCC -E -Q "SELECT @@VERSION"

If the service starts but freezes, check the SQL error log at C:\Program Files\Microsoft SQL Server\MSSQL10_50.WINCC\MSSQL\Log\ERRORLOG. Repair the instance using the WinCC / PCS 7 setup or by re-running setup.exe with the SQL Server option.

3.4 Industrial Ethernet card driver / protocol mismatch

PCS 7 V7.1 on Windows 7 64-bit frequently ships with a Broadcom NetXtreme or 3Com 3C905C-TX NIC for ISO-on-TCP S7 communication. After Windows updates or driver roll-backs, the ISO protocol binding in Simatic Shell → Settings may reference the wrong index, or the ISO module may not be installed. Simatic Shell shows the card as selected, but the S7 connection fails to bind, and the runtime blocks during initial handshake.

Check Command / Path Expected Result
NDIS driver loaded devmgmt.msc → Network Adapters Broadcom NetXtreme / 3Com "no error code 31 / 10"
ISO protocol installed ncpa.cpl → NIC properties "ISO Protocol" check box is enabled
Simatic Shell selection Start → Simatic → Simatic Shell Card index points to the IE card, not the virtual Hyper-V / VPN adapter
S7 connection status WinCC Explorer → Tag Management → SIMATIC S7 PROTOCOL SUITE → right-click → System Parameters → Connection Status = "Connected" (green) within 10 s
Hyper-V, VPN, VMware NAT, and team adapters frequently claim a lower index in Windows. If the Simatic Shell card index points to one of these, the ISO frames never reach the PLC, and the RT will sit in a "wait for handshake" state without showing an error.

3.5 SIMATIC Batch integration residue

Adding a SIMATIC Batch (BATCH) application to the PC station's HW Config can leave BATCH-specific services (CCBatchSvr, BATCHLaunchCoordinator) registered and starting on OS boot. Even if the BATCH project is removed from WinCC Explorer, the services may still hold locks on the WinCC archive database. This is the most common cause of "the RT worked, then froze after adding a Batch application, and removing the application did not fix it" reports.

Resolution:

  1. Open the PC station's HW Config in STEP 7.
  2. Remove the BATCH application object.
  3. Run Station Configuration Editor → Check until the configuration is consistent.
  4. Reboot. Verify in services.msc that no CCBatch / BATCH* service is still Running.

Compatibility note: on PCS 7 V7.1, the supported SIMATIC Batch version range is V7.1 SPx. Verify the installed BATCH build against the PCS 7 V7.1 compatibility list before reinstalling.

4. Diagnostic Procedure

Follow this sequence in order. Stop at the first step that resolves the issue and document which one fixed it for the site log.

  1. Capture the freeze evidence. Screenshot the operator screen and WinCC Explorer, then export the runtime event log via WinCC Explorer → Tools → Output Window → Save As.
  2. Check the Windows Event Viewer for MSMQ errors (source MQTT / MSMQ) and SQL errors (source MSSQL$WINCC) in the last 30 minutes.
  3. Verify MSMQ as described in §3.2.
  4. Verify SQL Server as described in §3.3.
  5. Re-run the OS Project Editor as described in §3.1.
  6. Audit the network card as described in §3.4.
  7. Audit BATCH residue as described in §3.5.
  8. Smoke test on a clean PC. Copy the project to a second PC station with a fresh OS image. If the RT runs there, the issue is local to the original station's environment (drivers, services, or Windows updates).

5. Step-by-Step Solution Walkthrough

The following procedure rebuilds the most common failure layer in the order Siemens support typically applies it.

5.1 Prerequisites

  • Local administrator on the WinCC server.
  • WinCC project license (Soft-PLC key) available.
  • STEP 7 / PCS 7 engineering license on the ES station.
  • Image / backup of the PC station before changes.

5.2 Stop and clean

net stop "SIMATIC WinCC Explorer"
net stop "CCAlgLogServer"
net stop "CCTagLogServer"
net stop "CCProjectMgr"
net stop MSSQL$WINCC

5.3 Re-initialize MSMQ

  1. Run appwiz.cpl → Turn Windows features on or off.
  2. Uncheck Message Queuing, reboot, re-check it, reboot again.
  3. Verify: sc query msmq shows STATE: 4 RUNNING.

5.4 Repair the SQL instance

  1. Insert the PCS 7 V7.1 DVD.
  2. Run setup.exe and choose Repair → Microsoft SQL Server 2005 / 2008 depending on the installed instance.
  3. After the repair, run osql -E -S .\WINCC and execute:
    USE master
    GO
    DBCC CHECKDB('CC_Alarms_<PROJECT>_<DATE>')
    DBCC CHECKDB('CC_Process_<PROJECT>_<DATE>')
    GO
  4. Restart the SQL instance and the WinCC services.

5.5 Re-run the OS Project Editor

Open WinCC Explorer, navigate to the OS, right-click → Open OS Project Editor, accept the default mapping on each tab (Picture tree, Alarm classes, User archive, Authorization, Picture blocks, OPC), click Apply, then OK. This regenerates the PDL cross-references and the alarm archive.

5.6 Verify the network binding

  1. Open Simatic Shell, Settings → confirm the IE card index.
  2. Open NetPro on the ES, double-click the S7 connection, Test → Connection test. Expect: Connection established within 5 s.
  3. From the WinCC server, run ping -S <PC-station-IP> <PLC-IP>. ISO traffic must not be filtered by a host firewall.

5.7 Clean BATCH residue

See §3.5. After the HW Config is clean, reboot and verify with sc query state= all | findstr /I "batch" – the result should be empty.

6. Verification

After the fix, confirm the runtime is fully functional, not merely "started".

Verification Expected Result Threshold
Click any softkey at the bottom of the screen Picture changes, login dialog opens, alarm list populates < 1 s
Trigger a PLC-side process alarm Alarm appears with the correct class color < 3 s
Open the tag-log online trend Online tag updates visible < 2 s
Plant hierarchy (PH) top bar All area / unit entries populated No blank cells
Process Historian / SQL archive New rows in CC_Process_* every 1 s Continuous
Stop via the X button on the picture Clean shutdown, services stop in < 30 s No "service hung" message

For broader RT Professional settings, refer to Configuring operation in Runtime (Professional).

7. Common Side Effects After Repair

  • Alarm classes reset to defaults. The OS Project Editor rebuilds the alarm-class color map; re-apply any custom red / blue / cyan definitions.
  • User archive empty. If the SQL repair re-creates the user archive DB, re-import the CSV via User Archive → Restore.
  • Licensed tags demote to internal. The WinCC License Viewer may show a "license broken" status after the services restart. Re-apply the soft-key license.
  • Time-zone drift on archives. After MSMQ rebuild, tag-log timestamps may be in UTC. Set the WinCC Time Configuration to Local time and restart.

8. Preventive Maintenance

  • Schedule the OS Project Editor run as a post-modification step in the change management procedure.
  • Exclude C:\Program Files\Siemens\Automation and the SQL data directories from antivirus real-time scanning.
  • Snapshot the PC station image before any Windows cumulative update.
  • Keep MSMQ on Automatic (Delayed Start) and verify quarterly with sc query msmq.
  • Verify the SIMATIC Batch compatibility matrix on every PCS 7 service pack upgrade.

9. Fault Code Cross-Reference

Symptom WinCC / Windows Event ID Likely Cause Reference
RT hangs at start, alarm list blank Application 1001 (MSMQ not started) MSMQ disabled SIOS 109766432
RT starts, no PH entries Application 7011 (CCProjectMgr timeout) OS Project Editor not run PCS 7 manual
RT starts, connection gray S7 driver error 0xFFD40001 Wrong NIC index in Simatic Shell PCS 7 manual, NIC driver KB
RT starts, archive empty SQL error 9001, 9002 MSSQL$WINCC log full / corrupted WinCC Commissioning
RT starts, BATCH service running Service 8005 timeout BATCH residue in HW Config SIMATIC Batch manual

10. Quick Reference Checklist

  • [ ] MSMQ service running, type Automatic (Delayed Start).
  • [ ] MSSQL$WINCC running, SELECT @@VERSION returns successfully.
  • [ ] OS Project Editor last-run timestamp matches the latest project change.
  • [ ] Simatic Shell card index points to the physical IE card.
  • [ ] No BATCH services running if BATCH is not licensed on this station.
  • [ ] Windows Event Viewer clean for the last 15 minutes.
  • [ ] PLC-side connection test in NetPro returns Established.

11. Frequently Asked Questions

Why does WinCC Runtime freeze immediately after activation in PCS 7 V7.1?

The most common cause on PCS 7 V7.1 is the Windows Message Queuing (MSMQ) service being disabled, which blocks Alarm/Tag Logging at startup. Other frequent causes are a corrupted MSSQL$WINCC instance, a network-card index pointing to the wrong adapter, and a missing OS Project Editor execution. Refer to Siemens KB 109766432.

How do I confirm that the SQL Server instance is the freeze point?

Run sc query MSSQL$WINCC and sqlcmd -S .\WINCC -E -Q "SELECT @@VERSION". If the service is stopped or the query hangs, restart the instance and re-check the SQL error log at ...MSSQL10_50.WINCC\MSSQL\Log\ERRORLOG. Repair the instance from the PCS 7 DVD if the database integrity check fails.

What is the role of the OS Project Editor in this symptom?

The OS Project Editor regenerates the picture tree, alarm-class mapping, user archive, and authorization tables in the WinCC database. If it is not re-run after project changes, the runtime can load the picture tree but blocks during alarm initialization, producing the apparent freeze and an empty plant hierarchy.

Why does the network card show in Simatic Shell but the runtime still hangs?

Simatic Shell may list the correct physical NIC while the ISO protocol binding still points to a lower-indexed virtual adapter (Hyper-V, VPN, VMware NAT). Verify the card index in Simatic Shell → Settings and re-enable the ISO Protocol on the physical IE card via ncpa.cpl.

Can adding a SIMATIC Batch application break an otherwise running WinCC Runtime?

Yes. Adding a BATCH application to the PC station's HW Config registers BATCH-specific Windows services that may continue running even after the BATCH project is removed from WinCC Explorer. The services can hold locks on the WinCC archive database, causing a freeze at start. Remove the BATCH application from HW Config, re-run the Station Configuration Editor, reboot, and confirm with sc query state= all | findstr /I "batch".

Back to blog